This document provides notes on the ten domains covered by the CISSP certification. It summarizes key concepts in security management practices such as risk analysis, data classification, roles and responsibilities, and policies/standards. Example government and public data classification terms are given. Steps in risk analysis include identifying risks, analyzing potential threats, and defining the Annualized Loss Expectancy. Risk reduction techniques include implementing controls, getting insurance, and accepting risks.